Data Haven is the searchable retention layer of the Realm Platform. All your log data is kept automatically. When an investigation needs older data, you search your full history and resupply the exact events you need.
Because the SIEM charges by ingest, teams push older telemetry into cheaper storage. It solves the cost issue and creates a new problem: when you need that data back, it's difficult to get it.
You can't see inside stored data to target the events you want, so you pull back a coarse, oversized range.
You pay to bring back far more than you need, then wait for it to land while the incident runs.
You search the raw result manually for the few records that count. And some data may have been filtered out and never kept at all.
As volumes climb year over year, the gap between what is stored and what is usable only widens.
A complete raw copy of all your security data, retained automatically with OCSF observables attached. Your full history stays complete and audit-ready in one place.
Search your entire history directly, using the observables your SOC already works in. No rebuild before you query. Find the exact events and resupply only those, anywhere.
Your data stays yours in an open, portable format. Keep as much as you want, as long as you want, with no storage cap. Send it anywhere. Never run infrastructure to do it.
Every connected source routes to Data Haven and keeps a complete, immutable raw copy, in an encrypted open format alongside its OCSF fields, observables, and enrichments.
Query your entire OCSF-normalized history by time range, source, and observable. A graphical query builder means no new query language to learn.
Send only the events you found to the destination you choose. No coarse restore, no manual dig, no wait.
An archive tier and a data lake can both store your history. In both, the data is frozen until you rebuild it, or expensive to search.
| Approach | Search your history | Cost to use it |
|---|---|---|
| Data Haven | Complete capture, searchable in place with no rebuild. | Priced on ingest. Search and resupply as much as you need. |
| SIEM archive tier | Slow to restore. Frozen until you thaw and rebuild it. | Pay compute to retrieve and query. |
| General-purpose data lake | Build schemas and transforms before anything is queryable. | The engineering and upkeep to run it. |
| Metered stores | Searchable, but you pay per scan every query. | Charges stack up mid-investigation. |
Data Haven is the searchable retention layer of the Realm Platform. It keeps an immutable raw copy of your security data with OCSF-normalized observables attached, and lets you search your full history directly, then resupply the exact events you need to any destination.
It is purpose-built for security and fully managed , so there is no infrastructure to stand up or run.
A SIEM runs real-time detection, correlation, and alerting on recent data. A searchable retention layer holds your full security history affordably and lets you search and retrieve older events on demand.
Data Haven is a retention layer, not a SIEM : it feeds your SIEM and detection stack, it does not replace them. Detection and alerting stay in the SIEM.
A security data lake is a general-purpose toolkit you build on and operate, which means schemas, transforms, and the engineering to run it.
Data Haven is purpose-built for security and fully managed: data lands normalized and immediately searchable on observables, with nothing to set up or maintain. You get the retention and the search without the build.
Use a retention layer that keeps data in a searchable format so you can query it in place, instead of a cold archive that freezes logs and forces a rebuild first.
With Data Haven, logs are captured automatically and stay searchable: you query your history on OCSF-normalized observables and retrieve only the exact events you need, with no rebuild step . This turns log retrieval from a slow batch process into a direct search.
Data Haven is priced on what you ingest, not on how much you query or retrieve. You can search and pull data as much as an investigation needs without per-query or per-access charges stacking up.
This is the difference from metered stores like Sumo Logic, which charge per scan on every query.
Yes. Data Haven encrypts data at rest and in transit, and stores it as an immutable copy, so your raw logs are preserved and attestable. Your retained history stays intact whether or not you resupply from it.
Searches and resupplies are logged, so you have a record of who accessed what and when. Role-based access lets you scope data sources to specific user groups.
The 7-Day Data Assessment. You pick a source, usually firewall logs. We do everything else, and deliver your reduction, detection integrity, and ROI on your own data in a week.
Start a 7-Day Data Assessment →Adding {{itemName}} to cart
Added {{itemName}} to cart